> ## Documentation Index
> Fetch the complete documentation index at: https://tonelloandco.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloud Onboarding

> This topic describes how to connect your AWS, Azure, GCP and OCI environments to Sysdig Secure. Click a tab below to select the platform you want to set up. You can connect Single Accounts or entire Organization Accounts using Terraform or CloudFormation.

<Tabs>
  <Tab title="AWS" icon="aws">
    # AWS

    <video controls className="w-full aspect-video rounded-xl" src="https://mintcdn.com/tonelloandco/GmtI0XaKgwIRxAL3/video/onboarding01_1080.mp4?fit=max&auto=format&n=GmtI0XaKgwIRxAL3&q=85&s=a92c76065e9af8315a39207050273bb5" data-path="video/onboarding01_1080.mp4" />

    ## 1. Prerequisites

    * A **Sysdig Secure administrator** account.
    * An **AWS user or role** with permission to install [IAM policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/id.html), as shown in the table below.
    * A local workstation with **Terraform v1.5+** installed or access to **CloudFormation**.
    * <a href="https://docs.sysdig.com/en/sysdig-secure/connect-aws/" data-ask-ai>Docs Help</a>
    * <a href="#" data-ask-ai data-query="onboard aws">Onboard AWS Help</a>

    <Accordion title="Click to Learn More About Using Terraform and AWS CLI" icon="square-chevron-right">
      import TerraformSnippet from '/snippets/terraform-snippet.mdx';

      <TerraformSnippet />
    </Accordion>

    <Accordion title="Click to Learn More About IAM Permissions" icon="circle-question">
      | Access | Description |
      | - | - |
      | [IAMFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/IAMFullAccess.html) | Required to create IAM Roles and associated permissions. |
      | [AWSOrganizationsReadOnlyAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSOrganizationsReadOnlyAccess.html) | Required to list Accounts and OUIDs in your Organization. |
      | [AWSCloudFormationFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCloudFormationFullAccess.html) | Required to create a CloudFormation StackSet that creates IAM roles in each Account in your Organization. |

      Only `IAMFullAccess` is required for individual accounts.
    </Accordion>

    ## 2. Collect Your Account Details

    <div style={{ float:"right",padding:"10px" }}>
      <img src="https://mintcdn.com/tonelloandco/GmtI0XaKgwIRxAL3/images/aws_account_id_small.png?fit=max&auto=format&n=GmtI0XaKgwIRxAL3&q=85&s=9babad086e403204ced79387141bd29e" style={{ height:"auto",width:"200px" }} width="459" height="351" data-path="images/aws_account_id_small.png" />
    </div>

    * Sign in to the **AWS Console**. For an **Organization**, ensure you sign in to your organization's management account.
    * Expand the dropdown in the top right corner of the **AWS Console** and copy your **Account ID**.

      You can also get your AWS AccountID by using this command via AWS CLI or the AWS Console terminal:

      ```
      aws sts get-caller-identity \
          --query Account \
          --output text
      ```
    * *Optional Organization Unit IDs.* By default, your entire AWS Organization will be onboarded. If you want to restrict onboarding to a subset of your Organization, you can gather specific OUIDs now and enter them in the following steps.

    ## 3. Connect with Terraform

    <div style={{ float:"right",padding:"10px" }}>
      <img src="https://mintcdn.com/tonelloandco/GmtI0XaKgwIRxAL3/images/wizard.png?fit=max&auto=format&n=GmtI0XaKgwIRxAL3&q=85&s=42d77f4b024ad392be2194aa96669f6d" width="400" data-path="images/wizard.png" />
    </div>

    <Steps>
      <Step title="Log in">
        Log in to **Sysdig Secure**.
      </Step>

      <Step title="Click Integrations">
        Click **Integrations** at the bottom of the main left-hand navigation menu, and choose **AWS Cloud Accounts**.
      </Step>

      <Step title="Choose account type">
        Choose whether to connect an AWS **Organization** or a **Single Account**.
      </Step>

      <Step title="Enter IDs and region">
        For **Organization** accounts, in Step 2, enter your **AWS management Account ID** and select your **Primary Region**. For **Single Accounts**, enter only your **AWS Account ID**.
      </Step>

      <Step title="Enter OUIDs">
        In Step 3, you can onboard a subset of your Organization Accounts by entering the OUIDs in a comma-separated list. Leave the field blank to onboard your entire Organization.
      </Step>

      <Step title="Generate Terraform file">
        In Step 4, click the **Next** button to generate a `main.tf` file to use with Terraform. Copy its contents and paste them into a new file, or download the file to an empty folder on your workstation, such as `/home/user/sysdig_onboarding`.
      </Step>

      <Step title="Execute Terraform">
        * On your **workstation**, navigate using the CLI to the folder containing your main.tf file and execute the following commands:

        ```bash theme={null}
        $ cd /home/user/sysdig_onboarding   # Your main.tf file location
        $ terraform init && terraform apply
        ```
      </Step>

      <Step title="Complete Onboarding">
        * When Terraform completes, click the **Complete Onboarding** button in the Sysdig Secure dashboard. Your newly added account will appear in the **Cloud Accounts** page.
      </Step>
    </Steps>

    ## 4. Connect with CloudFormation

    * Log in to **Sysdig Secure**.
    * In a separate browser window, log in to your **AWS Account**. For Organization installs, be sure to log in to your Organization's Management Account.
    * For **Organization** accounts, in Step 2, enter your **AWS management account ID** and your OUID(s). For a **Single Account**, enter only your **AWS Account ID**.
    * In Step 3, click the **Launch Stack** button. This will shift you to an **AWS console** browser window. Follow any prompts in AWS to deploy the required resources, and be sure to check the Acknowledgements in the AWS Capabilities section.
    * When CloudFormation completes, click the **Complete Onboarding** button in the Sysdig dashboard. Your newly added account will appear in the Cloud Accounts page.

    ## 5. Check the Connection

    * To validate your AWS connection, navigate to Sysdig Secure's **Integrations** > **Environments** > **AWS**.
    * Click the **Added On** column heading to show the most recently added account on top.
    * The **Status** column shows the overall connection status:
      * Connected
      * Error
      * Needs Attention
      * Unknown

    Select the desired AWS account to review the individual services in the detail drawer. There you can view the status of each feature you've enabled.

    <Accordion title="See an Example of the Health Status for CSPM" icon="circle-question">
      | **CSPM Status** | **Description** |
      | - | - |
      | ✅ **Healthy** | The account has been successfully connected, and all the resources have been scanned. |
      | **! Needs Attention** | Some features are not working properly. |
      | ❌ **Error** | Authentication errors. For example: <ul>                                    <li>                                    Invalid account ID</li>                                                                        <li>                                    Invalid client secret</li>                                                                        <li>                                    Invalid access credentials</li>                                                                        <li>                                    Access token errors</li>                                                                        <li>                                    Deny policy created by the user is preventing Sysdig from collecting resources</li>                                                                        <li>                                    The scan takes too long and eventually times out.</li>                                                                        <li>                                    Unknown error</li>                                                                        </ul> |
    </Accordion>

    ## Further Reading

    <Accordion title="Learn More About Permissions" icon="circle-question">
      ### Permissions Granted to Sysdig

      The above installation creates two IAM Roles that Sysdig can access. These Roles have the following permissions:

      * A role named `sysdig-secure-onboarding-XXXX`, used to manage the base integration with Sysdig
        * AWSAccountManagementReadOnlyAccess
        * AWSOrganizationsReadOnlyAccess (Organizational install)
      * A role named `sysdig-secure-posture-XXXX`, used to collect an inventory of cloud resources and perform CSPM
        * SecurityAudit
        * A Custom IAM Policy containing the following permissions:
          * `account:GetContactInformation`
          * `elasticfilesystem:DescribeAccessPoints`
          * `lambda:GetFunction`
          * `lambda:GetRuntimeManagementConfig`
          * `macie2:ListClassificationJobs`
          * `waf-regional:ListRuleGroups`
          * `waf-regional:ListRules`
          * `bedrock:ListAgents`
          * `bedrock:GetAgent`
          * `bedrock:ListKnowledgeBases`
          * `bedrock:GetKnowledgeBase`
          * `bedrock:ListGuardrails`
          * `bedrock:GetGuardrail`
          * `bedrock:GetModelInvocationLoggingConfiguration`
    </Accordion>

    <Accordion title="Learn More About Identities Shared with Sysdig" icon="circle-question">
      ### Identities

      Two [AWS identities](https://docs.aws.amazon.com/IAM/latest/UserGuide/id.html) are required in the onboarding process:

      * *Installer*: Either an AWS user or a role used to perform the onboarding. Sysdig does not have access to this identity.
      * *Sysdig*: A set of IAM Roles created during onboarding with specific, less permissive permissions attached. Sysdig is given access to these roles.
    </Accordion>

    [*(Original: https://docs.sysdig.com/en/sysdig-secure/connect-aws/)*](https://docs.sysdig.com/en/sysdig-secure/connect-aws/)
  </Tab>

  <Tab title="Azure" icon="microsoft">
    # Azure

    <Accordion title="Cloud Security Posture Management (CSPM)">
      **Cloud Security Posture Management (CSPM):**

      * Monitors and detects misconfigurations in your cloud resources.
      * Ensures your cloud environment complies with industry standards and regulations.
      * Provides a comprehensive inventory of all cloud assets, helping you maintain visibility and control over your environment.

      To enable CSPM, connect your Azure environment.
    </Accordion>

    <Accordion title="Review Azure Roles and Permissions">
      ### Security Principals

      The onboarding process involves two [security principals](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-principals):

      * Installer: The primary security principal, either a User or a Service Principal. This security principal will be used to perform the onboarding. Sysdig does not have access to this security principal.
      * Sysdig: A Service Principal (robot user) created during onboarding with specific, less permissive roles. Sysdig will be given access to this security principal.

      ### Azure Role Types

      Azure Identity and Access Management (IAM) is separated into two control planes:

      * [Entra ID Roles](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/custom-overview): Applied to the entire Tenant.
      * [Azure RBAC Roles](https://learn.microsoft.com/en-us/azure/role-based-access-control/overview): Applied to the Subscription or Management Group being onboarded.

      ## Prerequisites
    </Accordion>

    * Sysdig Secure SaaS with Admin permissions
    * Terraform v1.5.0+ installed
    * Azure CLI installed. See [How to install the Azure CLI](https://docs.microsoft.com/en-us/cli/azure/install-azure-cli).
    * A security principal with the permissions required to install, as mentioned in [Security Principals](https://docs.sysdig.com/en/sysdig-secure/connect-azure/#security-principals). For the required permissions, see [Permissions Required to Install](https://docs.sysdig.com/en/sysdig-secure/azure-permissions-and-resources/#base-azure-integration---cloud-security-posture-management-cspm). To grant permissions, you need:
      * `SP_ID`: Your Installer security principal ID. To retrieve this, open the Azure CLI and use the command `az ad sp list --display-name "terraform-runner" --query "[0].appId" --output tsv`.
      * `ROOT_MANAGEMENT_GROUP_ID`: Your Root Management Group ID. To retrieve this, open the Azure CLI and use the command `az account management-group list --query "[].{name:name, id:id}" --output tsv`.

    ## Prepare Your Environment

    ### 1. Configure Installation Permissions

    Ensure the principal you log in to Azure with has the [necessary roles and permissions](https://docs.sysdig.com/en/sysdig-secure/azure-permissions-and-resources/#base-azure-integration---cloud-security-posture-management-cspm) to install. You can:

    * Use an existing principal who meets the permissions requirements.
    * Create a new principal and set up permissions.
    * Add permissions to an existing principal.

    1. Log in to Azure.
    2. Check Entra ID Roles:
       * Navigate to the Entra ID console and select Roles and Administrators.
       * Verify and add necessary roles.
    3. Check Azure RBAC Roles:
       * For Single Subscriptions: Navigate to Subscriptions, select the target subscription, and verify roles.
       * For Management Groups: Navigate to Management Groups, select the target group, and verify roles.

    ### 2. Authenticate and Configure Terraform

    A common way to do this is:

    1. Ensure you are logged in to the correct Tenant.\
       Log in using the Azure CLI:

    ```
    az login --tenant "TENANT_ID_OR_DOMAIN"
    ```

    2. You will be presented with a web page to select your user account. Be sure to log in as the user you configured in Step 1.
    3. Confirm you are logged in as the correct user by running:

    ```
    az ad signed-in-user show

    ```

    4. For alternative ways to authenticate Terraform, see the Terraform documentation: [Authenticating to Azure Active Directory](https://registry.terraform.io/providers/hashicorp/azuread/latest/docs#authenticating-to-azure-active-directory) and [Authenticating to Azure](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs#authenticating-to-azure).

    ### 3. Collect your Azure Tenant ID and Subscription ID

    #### Tenant ID

    1. Sign in to the Azure portal.
    2. Navigate to Microsoft Entra ID > Properties.
    3. Scroll down to the Tenant ID section.
    4. Find your tenant ID in the box.
    5. Select the Copy to clipboard icon shown next to the Tenant ID.
    6. Store this value. You can paste this value into a text document or other location.

    #### Subscription ID

    1. Sign in to the Azure portal.
    2. Under the Azure services heading, select Subscriptions. If you don’t see Subscriptions here, use the search box to find it.
    3. Find the subscription in the list, and note the Subscription ID shown in the second column. If no subscriptions appear, or you don’t see the right one, you may need to switch directories to show the subscriptions from a different Microsoft Entra tenant.
    4. To easily copy the Subscription ID, select the subscription name to display more details. Select the Copy to clipboard icon shown next to the Subscription ID in the Essentials section. You can paste this value into a text document or other location.

    ## Install Azure Using the Wizard

    1. Log in to Sysdig Secure.
    2. Select Integrations > Cloud Accounts > Azure and click Add Azure Account on the top right corner.
    3. Connect your Azure [Tenant](https://docs.sysdig.com/en/sysdig-secure/connect-azure/#tenant-multi-subscription) or [Single Subscription](https://docs.sysdig.com/en/sysdig-secure/connect-azure/#single-subscription).
       * This enables CSPM and lets you onboard Vulnerability Management and CDR after completing the setup.

    ### Tenant Multi-Subscription

    1. Enter your:
       1. Tenant ID: The ID of the tenant you want to onboard.
       2. Subscription ID: The ID of the subscription where the Sysdig resources will be created.
    2. Specify Management Groups:
       1. For onboarding the entire Tenant: Enter Root Management Group ID.
       2. For a subset: Enter Management Group IDs in a comma-separated list.
    3. Generate and apply the Terraform code:
       1. Create a `main.tf` file.
       2. Copy the snippet provided into the file.
       3. Run the command: `terraform init && terraform apply`.

    Within an hour after deployment, your accounts will appear on the Cloud Accounts page.

    ### Single Subscription

    1. Enter your:
       1. Tenant ID: The ID of the tenant which contains the subscription you want to onboard.
       2. Subscription ID: The ID of the subscription you want to onboard.
    2. Generate and apply the Terraform code:
       1. Create a `main.tf` file.
       2. Copy the snippet provided into the file.
       3. Run the command: `terraform init && terraform apply`.

    Within an hour after deployment, your accounts will appear on the Cloud Accounts page.

    ## Check the Connection Status

    Within 5 minutes, after you apply Terraform, your accounts will appear on the Sysdig Cloud Accounts page. You can add more features after this initial connection by following instructions to [Add New Features](https://docs.sysdig.com/en/azure/add-new-features).

    You can verify your CSPM configuration by checking the connection status.

    1. In Sysdig Secure, select Integrations > Cloud Accounts > Azure.\
       The Status column shows the overall connection status:
       * Connected
       * Error
       * Unknown
    2. Select the desired account to review the individual services in the detail drawer.\
       The health status for CSPM configuration is given below:

    | CSPM Status | Description |
    | - | - |
    | Healthy ✅ | The account has been successfully connected, and all the resources have been scanned. |
    | Error ❌ | Authentication errors. For example: Invalid account ID Invalid client secret Invalid access credentials Access token errors Deny policy created by the user is preventing Sysdig from collecting resources The scan takes too long and eventually times out. Unknown error |
  </Tab>

  <Tab title="GCP" icon="google">
    # GCP
  </Tab>

  <Tab title="OCI" icon="infinity">
    # OCI
  </Tab>
</Tabs>
